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A method of issuing an electronic negotiable 
)cument (END) comprising: creating as data an END and 
storing this in a tamper-resistant document carrier, the. 
document carrier containing a unique public-secret key 
paiA for signing and verifying and a unique document 
carrier identifier; signing the unique document-carrier 
identr\fier, the END and an END identifier using the 
secret\key of the public-secret key pair and storing the 
result An the document carrier. 

2. A method according to Claim 1 of issuing an END, 
further comprising generating a time stamp representing 
the time ofXissue and storing this with the END in the 
tamper-resistant document carrier before the encryption 
step. 

3. A method ac^cording to Claim 1 or 2 of issuing an 
END, including ^he step of calculating a hash value of 
the END and/or tl^e time stamp value and storing this 
hash value instead\ of /the fii^l END in the 
tamper-resistant dd^u^e\t ^c^rrier, before the said 
encryption step. 

4. A method accordi/ngV to any preceding claim of issuing 
an END, in which the dobument carrier identifier, is a 
device number, and the E^D identifier is a serial 
number. 



5. A method according to smy preceding claim of. issuing 
an END, in which the END idehtifier is supplemented with 
data representing a water ma2?k unique to the issuer. 
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6. \a method according to any preceding claim of issuing 
an END, comprising the step of calculating a hash value 
of the data to be encrypted by the said secret key, in 
place \of the full data. 

7. A method according to any preceding claim of issuing 
an END, \ in which the document carrier stores a 
negotiability status flag indicative of whether the END 
stored tiierein is negotiable or non-negotiable, and 
including the step of setting the flag to "negotiable" 
after the result of the encryption has been stored in 
the document carrier. 

8. A method according to any preceding claim of issuing 
an END, in which the document carrier includes a counter 
for counting\a serial number, indicative of the number 
of times that\ the END has been negotiated since issue, 
and comprising the step of setting the counter to zero 
after the result of the encryption has been stored in 
the document carrier. 

9. A tamper-resMtant document carrier adapted to store 
an END in accordance with the method of any preceding 
claim, comprising read only software for controlling the 
steps of storing tha END, encrypting the END and other 
data with the pre-sto^ed secret key, and storing the 
result in a memory, 

10. A document carrier ^o6is;ding to Claim 9, in which 
the memory includes a negptiM status flag capable 
of being set either to '^^^^g^:^i^ble" or to 
" non- negotiable" . 

11. A document carrier 'accoi«iing to Claim 9 or 10, in 
which the memory includes a counter for storing a serial 
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number representative of the number of times the END has 
been negotiated. 

12. A method \of negotiating an END between a seller and 
a buyer each Possessing a tamper-resistant document 
carrier havini its own public-secret key pair, in which 
the END is stdred in the seller's document carrier in 
the form of END data, and the signature generated by the 
secret signingAkey of a document carrier of the issuer 
of the END, togtether with a negotiability status flag 
indicative of whether the END is currently negotiable 
from the document carrier on which it is stored, 
comprising establishing mutual recognition between the 
seller and buyer \using a predetermined protocol between 
the respective dofcument carriers, verifying in the 
seller's document! carrier that the negotiability status 
flag is "negotiable" and aborting the negotiation if 
not, sending the Jublic encryption key of the buyer' s 
document carrier tb the seller' s document carrier, and 
using it to encrypt the message comprising the END 
together with the liegoti ability status flag, sending 
that encrypted messkge to the buyer, decrypting that 
message using the biyer' s secret decryption key, and 
setting the negotiability status flag for that END of 
the buyex' s and sellir' s document carriers respectively 
to " non- negotiable" ahd "negotiable". 



13. A method of negotii^ting 
a buyer each possessin 
carrier having its own 
the END is stored in 
the form of END data, knd\ 
secret signing key of a 
of the END, together with 



an END between a seller and 
tamper-resistant document 
ic secret key pair, in which 
ler' s document carrier in 
e signature generated by the 
^cument carrier of the issuer 
serial number counter 
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indicative of the number of times that the END has been 
negotiates since issue, comprising establishing mutual 
recogniticm between seller and buyer using a 
predetermined protocol between their respective document 
carriers, verifying in the seller's document carrier 
that the EN©, if it has been stored previously in that 
document cartrier, has a different counter value this 
time and is therefore negotiable, but aborting the 
negotiation itf it is not negotiable, sending the public' 
encryption key of the buyer' s document carrier to the 
seller' s docuntent carrier, and using it to encrypt the 
message comprising the END together with the counter, 
sending that encrypted message to the buyer, decrypting 
that message using the buyer' s secret decryption key, 
and incrementing the counter by one. 

14. A method accbrding to Claim 12 or 13, in which each 
document carrier \is installed originally with a 
certificate comprising a digital signature of its unique 
identifier and ofUts public key, 

15. A method accoraing to Claim 14, in which the 
certificate unique ro the document carrier on which the 
END was originally i\ssued is stored with the END in the 
seller' s document carrier. 



16. .A method according to Claim 14 or 15, in which the 
certificate of the buyer' s document carrier is sent to 
the seller' s document c\arrier in which it is 
authenticated and the nAgdtiatirOrtr is aborted if 
authenti cati on fails , 



17. A method accordingyto \any of Claims 12 to 16, in 
which the buyer' s documents carrier, after decrypting the 
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messageX using its secret key, verifies the signature of 
the issuW on the END, and informs the issuer in the 
event that authentifi cation fails. 

18. A method according to any of Claims 1 to 8 of 
issuing an END on a document-carrier followed by a, 
method of Wegotiating the END as claimed in any of 
Claims 12 to 17, 

19. A methou according to Claim 18 as appendant to Claim 
2, in whichWhe buyer' s document carrier, after 
decrypting tne message vith its secret key, verifies 
that the ENDUs still valid by taking its time stamp, 
and, if it hate expired, informs the issuer of this, and 
aborts the negotiation before implementing the counter 
or setting the\ negotiation status flag- 

20. A method according to any of Claims 12 to 19- 
including recovering the negotiation of an END which has 
previously broken down, by providing the buyer' s 
document-carrieiA with the necessary secret key which has 
been reproduced by the issuer or by a trusted third 
party. \ 

21. A method accoAiing to any of Claims 12 to 19 
including recovering an END lost from a primary 
docxijnent-carrier, ny activating a back-up 
document-carrier which has previously been provided with 
back-up data reproduced from the primary 
document-carrierN, 

22. A method accordinft^ Claim 20 or 21, comprising 
inhibiting the reccjvery until the expiry of the 
predetermined period oA validity of the END. 
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23. A method ofl negotiating an END, sold by a seller to 
a buyer, in whiiph the buyer splits the END 



electronically i 
negotiates thos€ 
buyers 



nto two or more parts and then 
parts separately to one or more further 



24. A method ad?S^r<^ng to Claim 23, in which each part 
is subjected to jt^e digital signature of the said 
buyer' s document carrier which effects the splitting. 




